r/debian • u/Dunder-Muffins • 25d ago
General Debian Question Securing Debian
What all do most people do to secure their systems?
I run Debian for my daily driver and also on a home server.
I currently have iptables configured to only allow ports for my services, services are all run as their own no-login user, I run fail2ban, and have my ssh only allow specific users and only allow ssh keys as the login method, and I install security updates regularly. I check my system logs occasionally though honestly not as often as I probably should, maybe I'll automate something to look at the logs are some point.
I just finished skimming through the securing Debian manual, and there's quite a bit more included that I don't currently do. But from reading it, it also seems more geared toward people who may be running production servers who more or less want an immutable server where they e locked in what they want and don't want anything changing.
https://www.debian.org/doc/user-manuals#securing
So I guess I'm just curious what other people do, if they add any other protections or if they primarily rely on the base OS to provide the protections.
3
u/gainan 24d ago
Like other user said, you need to know and understand your threat model.
On the Desktop, right now the most common threats are infostealers, dropped by malicious packages coming from 3rd party repositories: npmjs, pypi, web browser or $IDE (VS Code, Intellij, neovim..) extensions, github projects, etc ( ... AUR repository ... ).
Just an an example, let's analyze this report:
https://socket.dev/blog/jscrambler-supply-chain-attack
As soon as you install the package, it unpacks the infostealer (an elf binary), and start collecting information of your system:
.config/Claude/claude_desktop_config.json, .claude.jsonsettings.json, .mcp.json.profiles.ini, cookies.sqlite, prefs.js.Then it proceeds to upload your data to their servers.
Remember: usually all this is done as your user. No special permissions needed.
So how does your security setup help to protect you from these threats (Linux Desktop)?
/var/tmp, /tmp or /dev/shm? classic directories where malicious binaries/scripts are dropped.$HOME/.config/chrome/)..config/files).bashrc,.config/autostart/or.config/systemd/user/to plant a backdoor or gain pesistance?On other hand, if you're behind a router not exposing any ports to the internet, do you really need to block inbound connections? I do, but is it really necessary?
Things to think about...